Follow these steps to delete an alert policy exception using the CLI.
The syntax of the configuration command is as follows:
no policymgr signature {id <sigID> | name <sigName> | category <attackCategory> | all} interface {<portPair> | ALL | MGMT}
[src {<srcIP>/<prefix> | any | any-v6} [dst {<dstIP>/<prefix> | any | any-v6}]]The command variables are defined as follows:
<sigID>
The eight-digit signature ID for a single alert rule.
<sigName>
The signature name of the alert rules that address aspects of the same network vulnerability.
<attackCategory>
One of the following predefined attack categories:
Infection-Match—Alert rules perform full or partial matching to identify a URL pointing to a Web infection.
Domain-Match - Alert rules that identify Bott IOC domain alerts.
Malware-Callback—Alert rules that identify callback events, which include signature matches and communications with a botnet server.
Riskware—Alert rules that identify files that are similar to malware but are not intended to be malicious.
IPS—All IPS alert rules
Reconnaissance—IPS alert rules that detect reconnaissance activity (ping sweeps and port scans of ports, hosts, or networks) in progress and generate alerts when suspicious activity reaches a threshold.
Local-Signature—All custom alert rules, including custom IPS rules.
<portPair>
A monitoring port pair. See the Hardware Administration Guide for your appliance.
A—Monitoring ports labelled pether3 and pether4
B—Monitoring ports labelled pether5 and pether6
C—Monitoring ports labelled pether7 and pether8
D—Monitoring ports labelled pether9 and pether10
E—Monitoring ports labelled pether11 and pether12
F—Monitoring ports labelled pether13 and pether14
<srcIP>/<prefix>
A source host or subnet IPv4 or IPv6 address in CIDR format.
<dstIP>/<prefix>
A destination host or subnet IPv4 or IPv6 address in CIDR format.
<actionType>
An override action as described in Alert policy exception actions:
block, unblock, suppress, suppress-unblock, or default-action.
Prerequisites
Admin or Operator access to the appliance.
Go to configure mode.
hostname > enable hostname # configure terminal
View the list of alert policy exceptions.
hostname (config) # show policymgr signatures
Delete an alert policy exception.
To delete an exception for a single alert rule, specify the eight-digit rule ID
<sigID>by using the following form of the command:no policymgr signature id <sigID> [interface {<portPair> | ALL | MGMT} [src {<srcIP>/<prefix> | any | any-v6} [dst {<dstIP>/<prefix> | any | any-v6}]]]To delete an exception for the alert rules that address aspects of the same network vulnerability, specify the vulnerability name
<sigName>by using the following form of the command:no policymgr signature name <sigName> [interface {<portPair> | ALL | MGMT} [src {<srcIP>/<prefix> | any | any-v6} [dst {<dstIP>/<prefix> | any | any-v6}]]]To delete an exception for the alert rules that belong to the same predefined category, specify the attack category by using the following form of the command:
no policymgr signature category <attack> [interface {<portPair> | ALL | MGMT} [src {<srcIP>/<prefix> | any | any-v6} [dst {<dstIP>/<prefix> | any | any-v6}]]]To delete an exception for all signatures, use the following form of the command:
no policymgr signature name all interface {<portPair> | ALL | MGMT} [src {<srcIP>/<prefix> | any | any-v6} [dst {<dstIP>/<prefix> | any | any-v6}]]The following example deletes the alert policy exception that applies to traffic through appliance port pair A and matched by rules in the Infection-Match attack category:
hostname (config) # no policymgr signature category Infection-Match A
Check your changes.
hostname (config) # show policymgr signatures
Save your changes
hostname (config) # write memory